Cross-Site Scripting in Disqus Comment System Plugin for WordPress
CVE-2014-5345

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
19 August 2014

Summary

The Disqus Comment System plugin for WordPress contains a cross-site scripting (XSS) vulnerability in its upgrade.php file. This flaw allows remote attackers to inject arbitrary web scripts or HTML into a website by manipulating the 'step' parameter. Exploitation of this vulnerability can lead to unauthorized actions being executed on behalf of a user or the exposure of sensitive information. Users of affected versions are strongly advised to update to the latest version to mitigate the risk.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.